Agent skill

Abstract State Analyzer

by ArabelaTso in ArabelaTso/Skills-4-SE

Performs abstract interpretation over source code to infer possible program states, variable ranges, and data properties without executing the program.

Apache-2.0Auto-check passedSecurity

Install Abstract State Analyzer

skills CLI
$ npx skills add ArabelaTso/Skills-4-SE --skill abstract-state-analyzer -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ArabelaTso/Skills-4-SE abstract-state-analyzer --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ArabelaTso/Skills-4-SE.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/abstract-state-analyzer .claude/skills/abstract-state-analyzer && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
abstract-state-analyzer
GitHub stars
253
Token cost
~1.8k tokens
SKILL.md length
554 words
Files
4 (incl. references)
Skills in repo
170
Repo updated
First seen
Licence
Apache-2.0

At a glance

Performs abstract interpretation over source code to infer possible program states, variable ranges, and data properties without executing the program.

  • Works in 6 steps: Parse and Understand Code Structure → Select Abstract Domains → Initialize Abstract States → …
  • Analyzing code for potential runtime errors
  • SKILL.md covers Overview, Analysis Workflow, Complete Example and Language-Specific Considerations, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Abstract State Analyzer is an agent skill from ArabelaTso/Skills-4-SE. Performs abstract interpretation over source code to infer possible program states, variable ranges, and data properties without executing the program. Reports potential runtime errors including out-of-bounds accesses, null dereferences, type inconsistencies, division by zero, and integer overflows. Use when analyzing code for potential runtime errors, performing static analysis, checking safety properties, or verifying program behavior without execution.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/abstract_domains.md`, `references/analysis_patterns.md` and `references/language_specifics.md`).

It sits in Security, covering Static analysis and SAST. The repository describes itself as: A curated list of 180+ useful Claude Skills for Software Engineering and resources for customizing AI for SE workflows. The licence is Apache-2.0.

When your agent uses it

  • Analyzing code for potential runtime errors
  • Performing static analysis
  • Checking safety properties
  • Verifying program behavior without execution

Example prompts

  • “Use the abstract-state-analyzer skill to perform abstract interpretation over source code to infer possible program states, variable ranges, and…”
  • “/abstract-state-analyzer”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Parse and Understand Code Structure
  2. Select Abstract Domains
  3. Initialize Abstract States
  4. Perform Forward Analysis
  5. Detect Potential Errors
  6. Report Findings

What it can do on your machine

Read from SKILL.md and the folder at commit 4f38503. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are python).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Abstract State Analyzer loads about 1.8k tokens when it runs, and up to ~7.5k if it reads all its reference files. Until then it costs about 121 tokens; SKILL.md has 554 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~121
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~7.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ArabelaTso/Skills-4-SE at commit 4f38503, republished under its Apache-2.0 licence (© ArabelaTso). 554 words, ~1,774 tokens.

Download SKILL.mdSave it as .claude/skills/abstract-state-analyzer/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
abstract-state-analyzer
description
Performs abstract interpretation over source code to infer possible program states, variable ranges, and data properties without executing the program. Reports potential runtime errors including out-of-bounds accesses, null dereferences, type inconsistencies, division by zero, and integer overflows. Use when analyzing code for potential runtime errors, performing static analysis, checking safety properties, or verifying program behavior without execution.

Abstract State Analyzer

Overview

This skill performs abstract interpretation to statically analyze source code and infer possible program states, variable ranges, and data properties. It identifies potential runtime errors without executing the program.

Analysis Workflow

Step 1: Parse and Understand Code Structure

Analyze the code to identify:

  • Functions and their control flow
  • Variable declarations and types
  • Loops and conditionals
  • Array/buffer operations
  • Pointer/reference operations
  • Function calls and parameter passing
Step 2: Select Abstract Domains

Choose appropriate abstract domains based on the analysis goals:

Interval Domain: Track numeric variable ranges

  • Example: x ∈ [0, 100] means x is between 0 and 100
  • Good for: Array bounds checking, overflow detection

Sign Domain: Track whether values are positive, negative, or zero

  • Values: {+, -, 0, ⊤}
  • Good for: Division by zero, sign-dependent operations

Null Domain: Track whether pointers/references can be null

  • Values: {null, not-null, maybe-null, ⊤}
  • Good for: Null dereference detection

Type Domain: Track possible types of variables

  • Good for: Type consistency checking, dynamic language analysis

Combination: Use multiple domains together for more precise analysis

Step 3: Initialize Abstract States

Set initial abstract values for:

  • Function parameters (based on preconditions or ⊤ for unknown)
  • Global variables
  • Constants and literals

Example:

python
def process(arr, index):
    # Initial state:
    # arr: not-null (assumed)
    # index: ⊤ (unknown integer)
Step 4: Perform Forward Analysis

Propagate abstract states through the program:

Assignment: Update abstract value

python
x = 5
# x: [5, 5]

y = x + 3
# y: [8, 8]

Conditionals: Split into branches

python
if x > 10:
    # Branch 1: x ∈ [11, ∞]
else:
    # Branch 2: x ∈ [-∞, 10]

Loops: Iterate until fixpoint

python
i = 0
while i < n:
    # Iteration 1: i ∈ [0, 0]
    # Iteration 2: i ∈ [0, 1]
    # ...
    # Fixpoint: i ∈ [0, n-1]
    i += 1

Join Points: Merge states from multiple paths

python
if condition:
    x = 5  # x: [5, 5]
else:
    x = 10  # x: [10, 10]
# After join: x ∈ [5, 10]
Step 5: Detect Potential Errors

Check for violations at each operation:

Array Bounds:

python
arr[index]
# Check: index ∈ [0, len(arr)-1]?
# If index: ⊤ → Potential out-of-bounds
# If index: [0, 5] and len(arr) = 10 → Safe

Null Dereference:

python
ptr.field
# Check: ptr is not-null?
# If ptr: maybe-null → Potential null dereference

Division by Zero:

python
x / y
# Check: 0 ∉ y?
# If y: [1, 10] → Safe
# If y: [-5, 5] → Potential division by zero

Integer Overflow:

python
x = a * b
# Check: a * b within type bounds?
# If a: [1000, 2000], b: [1000, 2000] → Potential overflow for int32

Type Inconsistency:

python
result = func(arg)
# Check: arg type matches parameter type?
Step 6: Report Findings

For each potential error, report:

  1. Location: File, line number, function
  2. Error Type: Out-of-bounds, null dereference, etc.
  3. Abstract State: Variable values at the error point
  4. Severity: Definite error vs. potential error
  5. Explanation: Why the error might occur
  6. Suggestion: How to fix (add check, change bounds, etc.)
Show full SKILL.md (257 more words)Show less

Complete Example

python
def find_max(arr, n):
    if n <= 0:
        return None

    max_val = arr[0]
    i = 1
    while i < n:
        if arr[i] > max_val:
            max_val = arr[i]
        i += 1
    return max_val

Analysis:

Initial State:

  • arr: not-null (assumed)
  • n: ⊤ (unknown integer)

Line 2: if n <= 0

  • Branch 1 (n ≤ 0): n ∈ [-∞, 0]
  • Branch 2 (n > 0): n ∈ [1, ∞]

Line 3: return None (Branch 1)

  • Safe return

Line 5: max_val = arr[0] (Branch 2)

  • Access: arr[0]
  • Check: 0 < len(arr)?
  • POTENTIAL ERROR: arr length unknown, might be empty
  • State: max_val = arr[0], n ∈ [1, ∞]

Line 6: i = 1

  • State: i = [1, 1]

Line 7: while i < n

  • Loop invariant: i ∈ [1, n]
  • Fixpoint: i ∈ [1, n-1] inside loop

Line 8: if arr[i] > max_val

  • Access: arr[i] where i ∈ [1, n-1]
  • Check: i < len(arr)?
  • POTENTIAL ERROR: If n > len(arr), out-of-bounds access
  • State: max_val updated if arr[i] > max_val

Line 10: i += 1

  • State: i ∈ [2, n]

Report:

POTENTIAL ERRORS FOUND:

1. Out-of-Bounds Access
   Location: line 5, arr[0]
   State: n ∈ [1, ∞], arr length unknown
   Severity: Potential
   Explanation: Array 'arr' might be empty when n > 0
   Suggestion: Add check: if len(arr) == 0 or add precondition

2. Out-of-Bounds Access
   Location: line 8, arr[i]
   State: i ∈ [1, n-1], arr length unknown
   Severity: Potential
   Explanation: If n > len(arr), accessing beyond array bounds
   Suggestion: Add precondition: n <= len(arr) or check i < len(arr)

Language-Specific Considerations

C/C++
  • Track pointer arithmetic carefully
  • Consider undefined behavior (signed overflow, null dereference)
  • Analyze memory allocation/deallocation
  • Check buffer sizes for string operations
Python
  • Dynamic typing requires type domain
  • List/dict operations need bounds checking
  • None values require null domain
  • Consider duck typing and attribute access
Java
  • Null pointer exceptions
  • Array bounds (ArrayIndexOutOfBoundsException)
  • Integer overflow (silent wraparound)
  • Type casting (ClassCastException)
JavaScript
  • Undefined and null values
  • Type coercion issues
  • Array bounds (returns undefined, not error)
  • Property access on null/undefined

Handling Complexity

Widening for Loops

When loops don't converge quickly, apply widening:

python
# Instead of: [0, 0] → [0, 1] → [0, 2] → ...
# Widen to: [0, ∞]
Function Summaries

For called functions, use summaries instead of full analysis:

python
def helper(x):
    # Summary: returns x + 1, no errors
    return x + 1

# Use summary instead of analyzing helper body
Path Sensitivity

For complex conditionals, track path conditions:

python
if x > 0 and x < 10:
    # x ∈ [1, 9] (path-sensitive)
    # vs x ∈ [-∞, ∞] (path-insensitive)

References

For detailed information on abstract interpretation techniques and domains:

  • references/abstract_domains.md: Detailed abstract domain definitions and operations
  • references/analysis_patterns.md: Common analysis patterns for different error types
  • references/language_specifics.md: Language-specific analysis considerations

© ArabelaTso, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in skills/abstract-state-analyzer of ArabelaTso/Skills-4-SE.

  • SKILL.md
  • references/abstract_domains.md
  • references/analysis_patterns.md
  • references/language_specifics.md

Open the folder on GitHubat commit 4f38503

Compare with similar skills

Abstract State Analyzer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Abstract State Analyzer compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Abstract State Analyzer this skillArabelaTso/Skills-4-SE253—~1.8kAutomated safety check: PassApache-2.0
Semgrepvigolium/piolium1401 repos~2.4kAutomated safety check: NotesMIT
C To AstNarwhal-Lab/MagicSkills316—~1.1kAutomated safety check: PassMIT
Semgrep Security Scantrailofbits/skills7.4k—~3.7kAutomated safety check: NotesCC-BY-SA-4.0
LLM Sast ScannerSunWeb3Sec/llm-sast-scanner287—~6.2kAutomated safety check: PassNone
Sast SemgrepAgentSecOps/SecOpsAgentKit2202 repos~2.4kAutomated safety check: PassCustom licence

Similar skills

  • Semgrep

    vigolium/piolium

    Run Semgrep static analysis scan on a codebase using parallel subagents.

    140 GitHub starsUsed in 1 repo~2.4k tokens
    SecurityAuto-check: notes
  • C To Ast

    Narwhal-Lab/MagicSkills

    Parse C source code into an Abstract Syntax Tree (AST). An agent skill from Narwhal-Lab/MagicSkills.

    316 GitHub stars~1.1k tokensUpdated 6 mo ago
    SecurityAuto-check passed
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.4k GitHub stars~3.7k tokensUpdated yesterday
    SecurityAuto-check: notes
  • LLM Sast Scanner

    SunWeb3Sec/llm-sast-scanner

    General-purpose Static Application Security Testing (SAST) skill for code vulnerability analysis.

    287 GitHub stars~6.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Sast Semgrep

    AgentSecOps/SecOpsAgentKit

    Static application security testing (SAST) using Semgrep for vulnerability detection, security code review, and secure coding guidance with OWASP and CWE framework mapping.

    220 GitHub starsUsed in 2 repos~2.4k tokens
    SecurityAuto-check passed
  • Wp Phpstan

    Automattic/agent-skills

    A skill your agent uses when configuring, running, or fixing PHPStan static analysis in WordPress projects (plugins/themes/sites): phpstan.neon setup, baselines, WordPress-specific typing, and…

    211 GitHub starsUsed in 1 repo~1k tokens
    SecurityAuto-check passed

More from ArabelaTso/Skills-4-SE

All 170 skills in this repo
  • Framework Migration Assistant

    ArabelaTso/Skills-4-SE

    Automatically migrate Python web applications between frameworks (Flask → FastAPI, Django → FastAPI).

    253 GitHub stars~1.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Metamorphic Test Generator

    ArabelaTso/Skills-4-SE

    Generate test cases using metamorphic testing by applying transformations based on metamorphic properties.

    253 GitHub stars~798 tokensUpdated 1 mo ago
    Auto-check passed
  • Reproduction Trace Instrumenter

    ArabelaTso/Skills-4-SE

    Instruments programs to capture execution traces specifically for reproducing reported bugs, enabling consistent replay and diagnosis of failures.

    253 GitHub stars~2.4k tokensUpdated 1 mo ago
    Auto-check passed
  • Spring Mvc To Boot Migrator

    ArabelaTso/Skills-4-SE

    Automatically migrate Spring MVC applications to Spring Boot.

    253 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check passed
  • State Snapshot Instrumenter

    ArabelaTso/Skills-4-SE

    Instrument programs (Python, C/C++, Java) to capture snapshots of key program states at runtime, including variables, memory, and call stacks.

    253 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Abstract State Analyzer

What does Abstract State Analyzer do?

Performs abstract interpretation over source code to infer possible program states, variable ranges, and data properties without executing the program. Abstract State Analyzer is an agent skill from ArabelaTso/Skills-4-SE. Performs abstract interpretation over source code to infer possible program states, variable ranges, and data properties without executing the program.

When should I use Abstract State Analyzer?

Abstract State Analyzer fits situations like: analyzing code for potential runtime errors; performing static analysis; checking safety properties; verifying program behavior without execution.

How do I install Abstract State Analyzer in Claude Code?

Run `npx skills add ArabelaTso/Skills-4-SE --skill abstract-state-analyzer -a claude-code`. Or copy the skill folder (skills/abstract-state-analyzer in ArabelaTso/Skills-4-SE) into .claude/skills/abstract-state-analyzer in your project. Claude Code loads it when a task matches its description.

How do I install Abstract State Analyzer in Codex?

Run `npx skills add ArabelaTso/Skills-4-SE --skill abstract-state-analyzer -a codex`. Or copy the skill folder (skills/abstract-state-analyzer in ArabelaTso/Skills-4-SE) into .agents/skills/abstract-state-analyzer in your project. Codex loads it when a task matches its description.

Can I use Abstract State Analyzer in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ArabelaTso/Skills-4-SE --skill abstract-state-analyzer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/abstract-state-analyzer, .gemini/skills/abstract-state-analyzer, .github/skills/abstract-state-analyzer and .opencode/skills/abstract-state-analyzer in your project.

What does Abstract State Analyzer need to run?

SKILL.md names no scripts, command-line tools or credentials: Abstract State Analyzer is instructions for the agent only. Our summary lists: Python 3.

Does Abstract State Analyzer access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Abstract State Analyzer safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Abstract State Analyzer use?

Abstract State Analyzer is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Abstract State Analyzer use?

About 1.8k tokens (SKILL.md is roughly 7.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.7k tokens, read only when the agent opens those files.

What are the alternatives to Abstract State Analyzer?

Skills that share tags, products or a category with Abstract State Analyzer: Semgrep (vigolium/piolium, 140 stars), C To Ast (Narwhal-Lab/MagicSkills, 316 stars), Semgrep Security Scan (trailofbits/skills, 7.4k stars) and LLM Sast Scanner (SunWeb3Sec/llm-sast-scanner, 287 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Abstract State Analyzer?

ArabelaTso (a GitHub user) maintains it in ArabelaTso/Skills-4-SE, which has 253 GitHub stars. The repository holds 170 skills in this directory. The repository was last updated on August 21, 2026.

Source: ArabelaTso/Skills-4-SE on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.